Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 9.0.90Upgrade Apache Tomcat to 11.0.0Upgrade Apache Tomcat to 10.1.25 | Nov 7, 2024 | Nov 7, 2024 |
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Jan 21, 2026 | Jan 20, 2026 |
| Debian | — | Upgrade tomcat9Upgrade tomcat10 | Sep 25, 2024 | Sep 25, 2024 |
| Redhat_linux | — | Upgrade relaxngDatatypeUpgrade jackson-databindUpgrade apache-commons-langUpgrade python-nss-docUpgrade tomcat-jsp-2.3-apiUpgrade jssUpgrade idm-pki-acmeUpgrade python-nss-debugsourceUpgrade tomcat-admin-webappsUpgrade jackson-jaxrs-providersUpgrade jackson-jaxrs-json-providerUpgrade slf4j-jdk14Upgrade glassfish-jaxb-apiUpgrade xml-commons-apisUpgrade bea-stax-apiUpgrade resteasyUpgrade tomcat-libUpgrade jackson-annotationsUpgrade jackson-coreUpgrade jackson-module-jaxb-annotationsUpgrade idm-pki-symkey-debuginfoUpgrade pki-servlet-engineUpgrade python3-idm-pkiUpgrade slf4jUpgrade tomcatjssUpgrade velocityUpgrade idm-pki-base-javaUpgrade idm-pki-tools-debuginfoUpgrade stax-exUpgrade idm-pki-kraUpgrade ldapjdk-javadocUpgrade glassfish-fastinfosetUpgrade tomcat-servlet-4.0-apiUpgrade xsomUpgrade pki-core-debugsourceUpgrade idm-pki-symkeyUpgrade glassfish-jaxb-runtimeUpgrade jss-javadocUpgrade tomcatUpgrade jss-debugsourceUpgrade xalan-j2Upgrade apache-commons-collectionsUpgrade javassistUpgrade xerces-j2Upgrade idm-pki-baseUpgrade xml-commons-resolverUpgrade idm-pki-serverUpgrade glassfish-jaxb-coreUpgrade xmlstreambufferUpgrade jss-debuginfoUpgrade python3-nssUpgrade pki-core-debuginfoUpgrade apache-commons-netNo solution existsUpgrade pki-servlet-4.0-apiUpgrade tomcat-webappsUpgrade idm-pki-caUpgrade glassfish-jaxb-txw2Upgrade idm-pki-toolsUpgrade javassist-javadocUpgrade python3-nss-debuginfoUpgrade ldapjdkUpgrade tomcat-el-3.0-apiUpgrade tomcat-docs-webappUpgrade jakarta-commons-httpclient | Oct 31, 2024 | Sep 23, 2024 |
| Suse | — | Upgrade tomcat-libUpgrade tomcatUpgrade tomcat-javadocUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-webappsUpgrade tomcat-el-3_0-apiUpgrade tomcat-docs-webapp | Dec 5, 2025 | Oct 2, 2024 |
| Ubuntu | — | Upgrade libtomcat8-java (Ubuntu Pro)Upgrade libtomcat10-java (Ubuntu Pro)Upgrade tomcat8 (Ubuntu Pro)Upgrade tomcat9 (Ubuntu Pro)Upgrade tomcat10 (Ubuntu Pro)Upgrade libtomcat9-javaUpgrade libtomcat9-java (Ubuntu Pro) | Jun 11, 2025 | Nov 7, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub